CVE-2020-13883: XEE
In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-13883?
CVE-2020-13883 is a vulnerability that allows XXE (XML External Entity) attacks in WSO2 API Manager, WSO2 API Microgateway, and WSO2 IS as Key Manager.
What is the severity of CVE-2020-13883?
The severity of CVE-2020-13883 is medium, with a severity value of 6.7.
How does CVE-2020-13883 affect WSO2 API Manager?
CVE-2020-13883 allows XXE attacks during the addition or update of a Lifecycle in WSO2 API Manager.
How does CVE-2020-13883 affect WSO2 API Microgateway?
CVE-2020-13883 allows XXE attacks in WSO2 API Microgateway.
How does CVE-2020-13883 affect WSO2 IS as Key Manager?
CVE-2020-13883 allows XXE attacks in WSO2 IS as Key Manager.
How can I fix CVE-2020-13883?
To fix CVE-2020-13883, update WSO2 API Manager to version 3.0.1 or later, WSO2 API Microgateway to version 2.2.1 or later, and WSO2 IS as Key Manager to version 5.9.1 or later.
Where can I find more information about CVE-2020-13883?
You can find more information about CVE-2020-13883 in the security advisory WSO2-2020-0727 at the following link: https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-0727